rhysida ransomware impacted Skaff Group by encrypting 139,377 files across ~268 GB, including full HR dossiers with Lebanese national ID scans, passports, civil-status extracts, and employees’ private photo archives. The compromise also exposed banking data, payroll/payroll-module material, commerce and customer documents (including customs/export paperwork), impacting Lebanon #lebanon
Incident Details
- Victim: Skaff Group
- Sector: Other
- Country:
- Actor: rhysida
- Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=281
- Discovered: 2026-10-03T13:02:56.759867+00:00
- Published: 2026-10-03T13:02:32.599704+00:00
Information
- 139,377 files were exposed, totaling approximately 268 GB.
- Full HR dossiers were included, with around 40 scans of Lebanese national ID cards, a director’s passport, and civil-status extracts.
- Banking data was compromised, including employee account files at Byblos Bank, Cedrus Bank corporate card program details, banker contacts, and account statements.
- Payroll-related information was leaked, such as unpaid-salary analysis files, payroll module source code, and staff leave requests.
- Employees’ private family photo archives stored on the work server were also exposed.
- Commercial documents were affected, including price lists, proposals for Four Seasons and Les Galeries, customs and export documents from Dubai and Erbil, and customer claims.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.